DEV Community

Discussion on: When not to use package-lock.json

Collapse
 
lirantal profile image
Liran Tal

This is more of your own opinion Gajus than a best practice.
Mael has pointed out good reasons to use lockfiles.

2 articles I wrote to provide more context on lockfiles are:

  1. snyk.io/blog/making-sense-of-packa...
  2. if you use lockfiles, there's also a potential security issue that you should know about: snyk.io/blog/why-npm-lockfiles-can...